9The New Stack·security
npm supply-chain attack hides malware behind provenance attestations
AI summary
Security researchers disclosed an npm supply-chain attack that compromised more than 400 packages, including projects tied to Keyv and Cacheable. The attackers used stolen maintainer credentials and lifecycle hooks to spread malware, showing that provenance attestations do not guarantee package integrity once a trusted workflow is compromised.
In-depth analysis
AI-generated, audience-specific — grounded in this story.
Technologies in this story
Discussion
No comments yet. Start the discussion.